Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Zero‑Day API Authentication Bypass in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑76504) Enables Remote Admin Access

Cisco reports active exploitation of CVE‑2026‑76504, an API authentication‑bypass flaw in its SD‑WAN Manager that grants attackers admin control. The issue underscores the need for continuous API monitoring, rapid patching, and auditable evidence of access‑control hygiene.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
helpnetsecurity.com

Zero‑Day API Authentication Bypass in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑76504) Enables Remote Admin Access

What It Is – Cisco disclosed a newly‑found authentication‑bypass flaw (CVE‑2026‑76504) in the Catalyst SD‑WAN Manager console. The bug stems from improper URI‑encoding handling, allowing a crafted HTTP request to skip the authentication check and obtain admin‑level API access.

Exploitability – Cisco’s incident responders observed active exploitation in the wild as early as September 2026. No public proof‑of‑concept is required; the vulnerability is being leveraged in real attacks.

Affected Products – Cisco Catalyst SD‑WAN Manager releases 26.2, 26.1, 20.18, 20.15, 20.12, 20.9 and any version earlier than 20.9.

Why It Matters for Trust & Control Assurance

  • Access‑control integrity – The flaw demonstrates how a single API weakness can undermine the entire network‑management trust boundary, a core control objective across SOC 2, ISO 27001, NIST CSF and others.
  • Continuous monitoring – Detecting the IoCs (serviceproxy‑access.log, vmanage‑server.log) requires persistent log collection and automated correlation, providing audit‑ready evidence of control effectiveness.
  • Patch‑management evidence – Demonstrating timely remediation (patching to ≥ 20.9) is a tangible control‑assurance artifact that auditors and enterprise buyers demand.

Recommended Actions

  • Patch immediately to a fixed release (≥ 20.9).
  • Restrict internet exposure of the SD‑WAN manager; allow access only from vetted hosts and hardened ports.
  • Enable exhaustive API logging and forward logs to a SIEM for real‑time detection of the listed IoCs.
  • Conduct a post‑patch threat hunt – capture a device snapshot, search logs for the IoCs, and open a TAC case if anomalies appear.
  • Document the remediation in your control evidence repository to support audit readiness.

Source: Help Net Security – New Cisco SD‑WAN zero‑day exploited in‑the‑wild (CVE‑2026‑76504)

📰 Original Source
https://www.helpnetsecurity.com/2026/10/01/new-cisco-sd-wan-zero-day-exploited-in-the-wild-cve-2026-76504/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →